CVE-2020-14171: Medium severity atlassian bitbucket vulnerability
Published Jul 9, 2020
·Updated
Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack.
Affected Software
1 affected component
Atlassian Bitbucket>=4.9.0<7.2.4
Event History
Jul 9, 2020
CVE Published
via MITRE·05:17 PM
Data Sourced
via MITRE·05:17 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Bitbucket Server vulnerability?
The vulnerability ID for this Bitbucket Server vulnerability is CVE-2020-14171.
2
What is the severity of CVE-2020-14171?
The severity of CVE-2020-14171 is medium with a CVSS score of 6.5.
3
What is the affected software version range for CVE-2020-14171?
The affected software version range for CVE-2020-14171 is from version 4.9.0 before version 7.2.4.
4
How does CVE-2020-14171 allow remote attackers to exploit the vulnerability?
CVE-2020-14171 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack.
5
Is there a fix available for CVE-2020-14171?
Yes, it is recommended to upgrade Bitbucket Server to version 7.2.4 or later to fix CVE-2020-14171.